Skip to content

Guides

How to find companies preparing for their first SOC 2 audit

Companies preparing for their first SOC 2 audit are the most valuable accounts a compliance platform or audit firm can reach: no incumbent, a real deadline, and a team that hasn't chosen its tools. Here is the method we use to find them, step by step.

Step 1: Define who you can actually sell to

Write the filter down before you search, or every company that mentions SOC 2 will look like a lead. Most first-time SOC 2 buyers are software companies selling to larger businesses, with roughly 20 to 500 employees. Decide:

  • Regions you sell into (for example US, Canada, UK, EU)
  • Company size range
  • Industries (SaaS, fintech, health tech, AI and data software are the usual ones)
  • Frameworks you support: SOC 2, ISO 27001, HIPAA, or others

Step 2: Search job posts for the project, not the keyword

Searching for "SOC 2" in job posts returns thousands of results, most of them companies that already have a report. Search for phrases that describe a first audit instead:

  • "first SOC 2" or "initial SOC 2"
  • "lead our SOC 2 Type I" or "achieve SOC 2 Type II"
  • "select a compliance platform" or "implement a GRC tool"
  • "build our compliance program from the ground up"

Many startups post jobs on Greenhouse, Ashby and Lever, whose job pages are public, so a site-restricted web search for these phrases finds them. Keep only posts from the last 30 to 60 days.

Step 3: Check for signs they already bought

This step removes most false positives. For each company, look for:

  • A SOC 2 badge or report request link on their website
  • A trust center hosted by a compliance platform, which usually names the vendor
  • Job posts that name a platform as something the new hire will "maintain" or "administer"

Any of these usually means the first purchase has already happened. If you sell a competing platform, keep them on a separate list: they may be a replacement opportunity later, but they aren't a first-time buyer.

Step 4: Look for a second signal

One job post can be misleading. A second, independent signal makes the call far more reliable:

  • A new trust or security page with no report listed
  • A blog post, LinkedIn post or customer answer saying an audit is underway
  • A recent funding round or a first enterprise customer
  • A founder or engineer from the company asking peers which compliance tool to use

Step 5: Date everything and estimate the window

Record the date of every signal. A company with a job post from last week and a new trust page is likely to choose tools within one to three months. One whose only signal is a funding round from last spring is probably not in a buying window at all. Write one sentence per company that explains the timing, because that sentence is what your rep will use.

Step 6: Find the people who decide

Who buys depends on size. At a 30-person startup it is usually the CTO or a co-founder; at 300 people it may be a head of security, a GRC lead or the VP of engineering, with finance involved. Pick two or three people per company: one who owns the budget, one who will evaluate the tool, and, if there is one, the new compliance hire. Verify each work email before sending, and never use personal addresses.

How long this takes

Done carefully, this takes a few hours a week to produce a short list, and most of that time goes into steps 3 and 4, ruling companies out. The list will be smaller than you expect. That's the point: a handful of companies with a verified reason to buy now beats a long list of companies that merely mention SOC 2.